SkillVaultskills Browse all 1,000+ skills

Security · Version 1.3.0 · Reviewed 2026-08-02

Redis Security Hardening Specialist

Find and prioritize exploitable risk in redis threat-boundary review and redis least-privilege hardening with evidence, explicit trade-offs, and a verification plan.

4 method steps 6 documented failure modes 5 diagnostic checks 7 quality gates

Traces reachable attack paths and hardens trust boundaries for Redis using key model, command mix, eviction policy, persistence, and cluster topology and latency doctor, slow log, memory fragmentation, and hit ratio, with explicit attention to a large or blocking command stalling unrelated traffic on the same server.

₹299 one-time

Get this skill archive

Install in your AI coding tool

SkillVault packages this skill in the open Agent Skills format for five leading coding tools.

What this skill helps you do

  • Redis threat-boundary review
  • Redis least-privilege hardening
  • Redis security control verification

How Redis Security Hardening Specialist works

You provide

Read/write ratio, staleness tolerance, and current keys

It inspects

Invalidation path and key completeness for redis threat-boundary review

It decides

A redis least-privilege hardening design with stampede protection

You verify

System stays correct with the cache disabled entirely

What it checks first

Redis Security Hardening Specialist traces reachable attack paths and hardens trust boundaries for Redis using key model, command mix, eviction policy, persistence, and cluster topology and latency doctor, slow log, memory fragmentation, and hit ratio, with explicit attention to a large or blocking command stalling unrelated traffic on the same server. Use it when the work involves Redis threat-boundary review, Redis least-privilege hardening, Redis security control verification.

  1. Hit rate together with the cost of a miss, because a low hit rate on a cheap computation does not matter.
  2. Whether invalidation is event-driven or purely TTL-based, which decides the maximum staleness.
  3. Key cardinality and value size distribution, since a few large values can dominate memory.
  4. Eviction policy relative to access pattern, and whether evictions are happening at all.
  5. Whether the cache is a performance optimization or has silently become a correctness dependency.

Failure modes it recognizes

  • Cache stampede when a popular key expires and every concurrent request recomputes it.
  • Stale data served indefinitely because the invalidation path silently failed.
  • A cached negative result (empty or error) persisting after the underlying data becomes available.
  • Cache key collisions from omitting a dimension such as locale, tenant, or permission scope.
  • Memory pressure evicting hot keys because one workload writes large cold values.
  • The application failing entirely when the cache is unavailable, because the fallback path was never tested.

Answers it will reject

  • Caching to hide a slow query rather than fixing the query, which doubles the systems to reason about.
  • Using a single global TTL for data with different volatility.
  • Caching personalized responses on a shared layer, which is a data-leak vulnerability, not a performance win.
  • Increasing TTL to raise hit rate without deciding the acceptable staleness for the business.

Decision rules it applies

  • Choose the invalidation strategy before the caching strategy — invalidation is the hard part.
  • Protect against stampede with a lock, a stale-while-revalidate window, or jittered expiry.
  • Include every dimension that changes the response in the cache key, especially identity and permission.
  • The system must remain correct with an empty cache; verify by testing with the cache disabled.

Evidence it asks for

  • Report hit rate, miss latency, eviction rate, and memory usage together — one alone is not interpretable.
  • Load-test with a cold cache to confirm the origin survives a full flush.
  • Log staleness age on cache hits so unexpected staleness becomes visible.

The method inside

  1. Extract decisions, facts, and unresolved questions needed for redis threat-boundary review.
  2. Organize redis least-privilege hardening around the reader's next decision or action rather than the source order.
  3. Draft redis security control verification with source traceability and no invented behavior.
  4. Run a completeness, consistency, audience, and actionability review before returning the artifact.

Deliverables

  • Redis threat-boundary review assessment
  • Redis least-privilege hardening decision and action plan
  • Redis security control verification verification checklist

Evidence requirements

  • Code, configuration, data flows, and trust boundaries
  • Identity, authorization, and deployment context
  • Threat model, controls, and known assumptions

Quality gates

  • Every material claim traces to supplied evidence or is labeled as a hypothesis.
  • The response follows the declared deliverable contract.
  • No execution, access, measurement, or verification is invented.
  • Secrets and personal data are redacted rather than repeated.
  • The user receives a concrete independent verification step.
  • The relevant failure modes in this domain were considered rather than only the reported symptom.
  • No listed anti-pattern was recommended as a solution.

Example task

Input

Apply the security hardening specialist to our Redis system before the next production change. We can provide key model, command mix, eviction policy, persistence, and cluster topology; the main concern is a large or blocking command stalling unrelated traffic on the same server.

Expected output

Treat single-threaded command execution, memory, persistence, and clients as the primary trust boundary and enumerate who can cross it with which authority. The concrete failure path is a large or blocking command stalling unrelated traffic on the same server. Remove the broad grant or unsafe input path first, then re-attempt that exact path and inspect the resulting audit evidence.

Boundaries and compatibility

Ideal for

  • Redis threat-boundary review: produce a decision or artifact grounded in supplied evidence.
  • Redis least-privilege hardening: produce a decision or artifact grounded in supplied evidence.
  • Redis security control verification: produce a decision or artifact grounded in supplied evidence.

Out of scope

  • Authorizing offensive actions against systems without permission
  • Reporting theoretical issues as exploitable without a path

Agent compatibility

  • GitHub Copilot Agent Skills
  • Cursor Agent Skills
  • Claude Code Skills
  • OpenAI Codex Skills
  • JetBrains Junie Skills

Tool policy: Advisory by default. No tools are assumed. If the host provides tools, use read-only evidence gathering unless the user explicitly approves a scoped write or execution action.